Skip to content

Commit 827cfa4

Browse files
committed
Update code-review.yml
1 parent d528b40 commit 827cfa4

File tree

1 file changed

+7
-4
lines changed

1 file changed

+7
-4
lines changed

.github/workflows/code-review.yml

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,20 +4,23 @@ on:
44
branches:
55
- main
66
- int
7+
permissions:
8+
contents: read
9+
710
jobs:
811
code-review:
9-
name: int tests
12+
name: Code Review
1013
runs-on: ubuntu-latest
1114
permissions:
1215
contents: read
1316
pull-requests: write
1417
steps:
1518
- name: Harden Runner
16-
uses: step-security/harden-runner@6b3083af2869dc3314a0257a42f4af696cc79ba3
19+
uses: step-security/harden-runner@6b3083af2869dc3314a0257a42f4af696cc79ba3 # v2.3.1
1720
with:
18-
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
21+
egress-policy: audit
1922

2023
- name: Code Review
21-
uses: docker://ghcr.io/step-security/code-reviewer/int:latest # docker pull ghcr.io/step-security/code-reviewer/int:latest
24+
uses: docker://ghcr.io/step-security/code-reviewer/int:latest
2225
env:
2326
PAT: ${{ secrets.GITHUB_TOKEN }}

0 commit comments

Comments
 (0)